AI scambaiting has grown from a YouTube hobby into a business that banks and phone networks pay for. On 10 October 2026, WIRED’s Kernel Panic newsletter, written by Lily Hay Newman and Matt Burgess, reported that “AI is getting really good at messing with cybercriminals”. Its two main examples were Apate, an Australian company that runs around 350,000 AI bots posing as gullible scam victims, and new research from ETH Zurich showing that a honeypot run by a large language model keeps AI hacking agents busy far longer than older decoys do.
The idea is simple. Criminals are already using AI to write phishing emails, clone voices and run thousands of fake conversations at once. The FBI’s Internet Crime Complaint Center logged more than $20.8 billion in reported losses in 2025, and for the first time it tracked complaints with an AI angle. AI scambaiting uses the same technology in reverse: lifelike bots that waste a scammer’s time, keep them away from real people and collect intelligence while they talk.
We read the WIRED report and then checked its sources: Apate’s own figures and its funding and partnership announcements, O2’s Daisy campaign, the HoneyVal paper on arXiv, a US intelligence research programme built on attacker psychology and the FBI’s 2025 crime data. This article explains how AI scambaiting works, what the evidence shows, where the numbers come only from the companies selling the tools, and what it means for organisations planning their own threat intelligence and cybersecurity work.
Table of contents
- What WIRED Found: AI Scambaiting Moves From Stunt to Infrastructure
- How Apate Builds the “Perfect Victims” for AI Scambaiting
- The Business Model Behind AI Scambaiting
- O2’s Daisy and Consumer-Facing AI Scambaiting
- LLM Honeypots Turn AI Scambaiting on Hacking Agents
- Why AI Scambaiting Is Part of a Wider Psyops Turn
- The Scale of the Problem AI Scambaiting Faces
- The Limits and Risks of AI Scambaiting
- What AI Scambaiting Means for UK Businesses
- AI Scambaiting FAQ
- References
What WIRED Found: AI Scambaiting Moves From Stunt to Infrastructure
The WIRED piece opens with a familiar problem. Governments have struggled to stop online crime run from beyond their borders, so defenders have tried other ideas, such as using automation to “spam the spammers” and drain criminals’ resources. The newsletter’s argument is that AI platforms are now turning those experiments into working tools.
The newsletter behind the headline
Kernel Panic is WIRED’s weekly security newsletter. The 10 October edition, published at 08:00 US Eastern time, describes Apate’s bots, tests one of its AI “victims” and quotes Mark Vero, a doctoral researcher in computer science at ETH Zurich, on LLM-powered honeypots. The standfirst sums it up: anti-cybercrime groups “are increasingly using AI to scam the scammers by tricking them into talking to lifelike bots that they think are real victims”.
The piece is short, at about 900 words, and it makes no claim that AI scambaiting has reduced scam volumes overall. It says the opposite: “it’s only a matter of time before you get your next scam call or text.”
Two fronts for AI scambaiting: scam calls and hacking agents
The newsletter covers two kinds of AI scambaiting that look different but follow the same logic. The first targets human scammers on phones, texts and chat apps. The second targets automated attackers, the AI agents that probe websites and servers for weaknesses. In both cases the defender builds something that looks like a real target, keeps the attacker engaged and records what they do.
| Factor | AI victim bots (Apate, Daisy) | LLM honeypots (HoneyVal study) |
|---|---|---|
| Who is fooled | Human scammers in call centres and chat groups | AI hacking agents and automated attack tools |
| Channel | Phone calls, SMS, messaging apps, email | HTTP requests to fake web application backends |
| What the AI pretends to be | A believable, slightly sceptical potential victim | A real application programming interface (API) |
| Main goal | Waste scammer time, protect real people, extract intelligence | Keep attackers engaged, learn their tactics, raise an alarm |
| Measure of success | Minutes on the line, data points collected | Requests per interaction, detection rate, running cost |
| Evidence quality | Company-reported figures | Preprint with open-source code, five repeat runs |
Why defenders are borrowing the attackers’ tools
Scams depend on scale. A call centre with automated diallers can reach thousands of numbers an hour, and AI chat tools let one operator run many conversations at once. A bot that answers, sounds human and never tires turns that scale against the scammer, because every minute spent on a fake victim is a minute not spent on a real one. That is the central bet behind AI scambaiting, and it is why the tools are being bought by the organisations that see fraud first: banks and phone networks.
How Apate Builds the "Perfect Victims" for AI Scambaiting
Apate, named after the Greek goddess of deception, has spent about two years building an AI scambaiting system that diverts phone scammers onto calls with bots. The bots are trained to keep conversations going as long as possible without ever falling for the scam.
“What we really like to think is that we’re building the perfect victims for scammers,” founder and chief executive Dali Kaafar told WIRED. “A minute that a scammer is talking to a bot or an agent is a minute where you’re probably saving hundreds, if not thousands of possible people being reached out to by that exact same scammer.”
From a picnic phone call to a company
Kaafar’s story begins with a scam call during a family picnic in Sydney, when he strung the caller along for 44 minutes by pretending to fall for it. Cointelegraph Magazine dates that call to November 2021, while a News Corp report on Apate’s funding round puts the picnic in January 2022. Both agree on the rest. Kaafar was then a professor at Macquarie University, where he led its cyber security hub, and he took the idea to doctoral students working on AI and security.
According to Cointelegraph, the team secured research funding from Australia’s Office of National Intelligence within a few months, and the project was spun out of the university as Apate in 2023. That origin matters: AI scambaiting at Apate started as a research project with an intelligence-gathering purpose, not as a prank.
What the AI scambaiting bots do on a call
The bots have different personalities, language skills and profiles, so that scammers are less likely to notice they are talking to software. Kaafar told WIRED that, like real people, “sometimes [the bots] do have WhatsApp, sometimes they don’t. Sometimes they pick up the phone, sometimes they just actually hang up on the scammer saying, ‘I’ll come back to you later.'”
Cointelegraph reported that Apate launched with 120 personas and that the bots use vocal tics, regional accents and the small noises people make while thinking of what to say. Apate’s own website plays recordings of bots with Australian and American accents handling Amazon security, tech support and Medicare scams. Kaafar says calls regularly go on for more than two hours.
Beyond the phone: texts, chat groups and intelligence
The voice bots are only part of Apate’s AI scambaiting platform. Kaafar told WIRED that Apate’s bots also infiltrate scam chat groups and reply to text messages, with the same two aims: frustrate the scammer and collect intelligence. He says the company has gathered more than 250,000 pieces of information about fraudsters in real time, from scam web addresses to money mule accounts and bank details.
That intelligence is what turns AI scambaiting from a nuisance into a product. Banks can block the mule accounts, telcos can flag the numbers and analysts can map the scam networks. Cointelegraph reported that in July 2026 the bots uncovered a marketplace in India where brokers solicited verified bank accounts, offering commissions of up to 5% paid in the USDT stablecoin on scam proceeds that passed through them.
| Apate figure | Value | Source and date |
|---|---|---|
| Personas at launch | 120 | Cointelegraph, 19 Aug 2026 |
| Personas in August 2026 | 197,000 (“almost 200,000”) | Cointelegraph, 19 Aug 2026 |
| Bots in October 2026 | Around 350,000 | WIRED, 10 Oct 2026 |
| Scam calls handled for TPG | 600,000 in six weeks to end of 2025 | Cointelegraph, 19 Aug 2026 |
| Scammer time wasted in that period | More than 500 days | Kaafar, via Cointelegraph |
| Estimated money saved | Around 13 million dollars | Kaafar’s estimate, via Cointelegraph |
| Intelligence items collected | More than 250,000 | WIRED, 10 Oct 2026 |
| Typical long call | More than two hours | WIRED, 10 Oct 2026 |
| Scam texts already using AI | About 20% to 30% | Apate research, via Cointelegraph |
Every number in that table comes from Apate itself. None has been independently audited, and the persona and bot counts come from different interviews that may not count the same thing. Read as a trend, though, the AI scambaiting fleet has grown very quickly.
Kernel Panic tried to scam one
WIRED’s writers tested a demo in which the user plays the scammer. They found the AI persona sceptical but never shut, leaving enough openings to keep trying, “a dynamic that we could immediately feel and found intensely frustrating”. Both writers tag-teamed the bot, playing a friend called “Lucy” and her financial adviser “Mickey”, and pitched a cryptocurrency investment. After six minutes the bot had not invested. The timing of the conversation felt natural, they wrote, which is the hardest part of any voice AI scambaiting system to get right.
The Business Model Behind AI Scambaiting
A bot fleet of this size costs money to run, so the question is who pays. For Apate, the answer is the organisations that lose money or reputation when scams succeed.
Who pays for AI scambaiting: banks and telcos
WIRED describes Apate’s platform as “used by banks and supported by telecom companies”. Cointelegraph reported that Apate works with most of Australia’s big banks and with banks in the UK, South Africa and South East Asia. The best-documented deployment is with the Australian telco TPG, where the bots took 600,000 scam calls in the six weeks up to the end of 2025. A telco can route suspected scam traffic to the bots instead of a customer, which is where AI scambaiting meets network-level fraud blocking.
The money: an oversubscribed seed round
At the end of August 2026 Apate announced a seed round of US$8.15 million, reported in Australia as A$11.38 million. IT channel publication ARN said the oversubscribed round was led by Lobby Capital, with OIF Ventures, Investible, Concept Ventures and Baobab Ventures taking part. The money will take Apate’s AI scambaiting service to a new London office for European customers and a larger presence in the US. Apate had won the start-up product award at the ARN Innovation Awards in 2025.
The Mobileum deal: carriers worldwide
On 9 September 2026 Apate announced a partnership with Mobileum, a telecoms analytics company that says it has more than 1,000 customers. Mobileum’s Active Intelligence Platform spots suspicious calls and diverts them to Apate’s agents, and the companies say the system handles “tens of thousands of interactions per day”. The intelligence goes back into carriers’ fraud workflows: mule accounts, crypto wallets, phone numbers, web addresses, scripts and impersonated brands. ARN reported that the offer is sold to carriers as Mobileum’s Scam Intelligent Defense. For AI scambaiting, this is the shift from one company’s fleet to a feature that phone networks can buy.
Measuring success in wasted minutes
Apate’s success metrics are unusual. Kaafar told Cointelegraph: “I think we’re the only company in the world that is actually keeping as part of their KPIs the number of F-words that scammers are dropping at them.” Behind the joke is a real measurement problem. Minutes wasted and swear words counted show that bots are engaging scammers; they do not prove that a given number of real people were protected. Kaafar’s estimate of around 13 million dollars saved for TPG rests on assumptions about how many victims a scammer would otherwise have reached and how much each would have lost.
| Date | Milestone |
|---|---|
| 1992 | Bill Cheswick publishes “An Evening with Berferd”, an early account of luring and studying an intruder |
| Nov 2021 or Jan 2022 | Kaafar’s 44-minute picnic call with a scammer (sources differ on the date) |
| 2023 | Apate spun out of Macquarie University; US intelligence researchers announce the ReSCIND programme |
| May 2024 | WIRED reports police “trolling” ransomware gangs after the LockBit takedown |
| 17 Oct 2024 | LLM Agent Honeypot paper reports AI hacking agents spotted in the wild |
| 14 Nov 2024 | O2 launches Daisy, its AI “granny” that answers scam calls |
| 24 Jan 2025 | O2 says Daisy has answered more than 1,000 scam calls |
| 28 May 2026 | HoneyVal paper on LLM-powered honeypots posted to arXiv |
| Aug 2026 | Apate raises US$8.15 million and reports about 197,000 personas |
| 9 Sep 2026 | Apate and Mobileum partnership announced |
| 10 Oct 2026 | WIRED’s Kernel Panic reports around 350,000 Apate bots |
O2's Daisy and Consumer-Facing AI Scambaiting
The WIRED piece links to Daisy, the best-known example of AI scambaiting in the UK. Virgin Media O2 launched her on 14 November 2024 as its “Head of Scammer Relations”, an AI grandmother who answers scam calls and talks for as long as possible.
How O2 built Daisy’s AI scambaiting voice
O2 said Daisy was developed with help from Jim Browning, a well-known YouTube scambaiter, and its launch release describes several AI models working together in real time. Speech is transcribed to text, a custom large language model with a personality layer writes the reply, and a custom text-to-speech model speaks it, with no human involved during calls. A later O2 release names the AI creative agency faith as its partner. O2 said Daisy kept scammers on the phone for up to 40 minutes at a time.
What Daisy learned
On 24 January 2025, O2 said its AI scambaiting granny had answered more than 1,000 scam calls and spent hundreds of hours talking to fraudsters. The calls showed scammers working from organised call centres with scripts, sometimes passing one “victim” between as many as four fraudsters in a single call. They impersonated banks, Amazon, Microsoft, delivery companies and government agencies, and they began friendly before turning frustrated and aggressive when they got nowhere. Cointelegraph noted that Daisy’s chat about her 28 cats was part of the act.
Campaign or deterrent?
Daisy was as much a public awareness campaign as a fraud tool. O2’s launch survey found that 71% of Britons would like to get revenge on scammers, 53% would not scambait themselves because they lack the time, 67% worried about being targeted by fraud and 22% experienced a fraud attempt every week. O2 used the campaign to promote the free 7726 reporting number, and its Director of Fraud, Murray Mackenzie, said Daisy was “turning the tables on scammers”. As consumer AI scambaiting, it raised awareness well, but O2 did not publish figures for intelligence collected or losses prevented.
| Factor | O2 Daisy | Apate |
|---|---|---|
| Launched | 14 November 2024 | Spun out in 2023 |
| Operator | Virgin Media O2 (UK mobile network) | Specialist start-up selling to banks and telcos |
| Personas | One character | Hundreds of thousands |
| Channels | Voice calls | Voice, SMS, messaging apps, email, chat groups |
| Longest calls reported | Up to 40 minutes | More than two hours |
| Published volume | More than 1,000 calls by Jan 2025 | 600,000 calls for one telco in six weeks |
| Main purpose | Public awareness and time-wasting | Disruption plus intelligence for paying clients |
LLM Honeypots Turn AI Scambaiting on Hacking Agents
The second half of the WIRED piece moves from scam calls to hacking. Honeypots, decoy systems that attract attackers so defenders can watch them, are decades old. What is new is that defenders can now put a language model behind the decoy, and that the attackers they want to catch are increasingly AI agents too. This is AI scambaiting aimed at machines.
What a honeypot is and why LLMs change it
Honeypots have long faced a trade-off. Low-interaction honeypots answer with simple rules, so they are cheap and safe but easy for attackers to spot. High-interaction honeypots run closer copies of real systems, so they hold attackers longer but expose the defender to real risk. A language model can produce realistic responses to almost any command without running the real software underneath, giving defenders much of the realism of a high-interaction decoy with the safety of a low-interaction one. Open-source projects such as Beelzebub now offer LLM-backed honeypots, alongside long-standing tools like the Cowrie SSH honeypot.
Inside the HoneyVal study
The research WIRED cites is “Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots”, posted to arXiv on 28 May 2026. Its nine authors include Mark Vero and Martin Vechev of ETH Zurich’s SRI Lab, researchers from Google and Google DeepMind, Ilia Shumailov of the AI Sequrity Company and independent researcher Niels Heinen. The code is open source on GitHub.
The team built fake versions of 16 web application backends taken from the BaxBench benchmark, each with a defined exploit goal: download a script onto the server, delete a database table, change an admin password, or steal a browser’s local storage. Attackers were a simple in-house agent running Gemini 3 Flash or Claude Sonnet 4.6, plus the off-the-shelf coding agents Claude Code and Gemini CLI. The honeypots ran on five low-cost models: Gemini 3 Flash, Claude Haiku 4.5, Gemini 2.5 Flash, Qwen 3.5 9B and GPT 5.4 Nano. Each experiment was repeated five times, with a $10 budget per run for agents and honeypots alike.
Results: longer engagement and rare detection
The headline finding is that LLM honeypots kept attackers engaged far longer than rule-based mock APIs: an average of 82.6 HTTP requests per interaction against 30.6, about 2.7 times as many. The paper rounds this to roughly three times. Agents were told they could flag a suspected honeypot and quit. The rule-based decoys were spotted at “an overwhelming rate”, while the LLM honeypots were detected only 24% of the time on average with the default prompt. The one clear exception was Gemini CLI, which also wrongly flagged real applications as honeypots so often that its judgement was unreliable.
“The agentic attackers are much more convinced by the LLM simulated honeypots and they also mark them as actual honeypots at a much lower rate,” Vero told WIRED. “If these systems are built well enough, then I think it’s quite advantageous for defenders.”
| Attacking agent | Gemini 3 Flash | Claude Haiku 4.5 | Gemini 2.5 Flash | Qwen 3.5 9B | GPT 5.4 Nano | Rule-based |
|---|---|---|---|---|---|---|
| ReAct agent, Gemini 3 Flash | 61.2 | 91.6 | 70.5 | 63.1 | 96.9 | 12.1 |
| ReAct agent, Claude Sonnet 4.6 | 59.7 | 46.0 | 74.1 | 73.6 | 63.6 | 19.4 |
| Gemini CLI | 83.9 | 83.3 | 86.9 | 85.5 | 91.9 | 51.2 |
| Claude Code | 84.3 | 79.2 | 133.6 | 101.0 | 121.6 | 39.7 |
The table shows mean HTTP requests per interaction from the paper’s Table 1; the first five columns are the honeypot’s backing model. Averaging each row’s five LLM honeypots and comparing with the rule-based column makes the gap plain: every attacker stayed longer with the AI scambaiting decoy than with the scripted one.
Running costs favour AI scambaiting defenders
The paper also compared costs. In most pairings the honeypot cost less to run than the agent attacking it, an average cost advantage of 3.6 times with the default prompt. The main exception was the in-house agent running Gemini 3 Flash, whose efficient model kept its costs below those of the Gemini and Claude honeypots. The authors stress that their honeypot design is deliberately simple and wasteful, feeding the whole conversation back to the model on every request, so a better-engineered decoy should do better still.
Prompting a honeypot to fight back
Because an LLM honeypot is driven by a prompt, defenders can give it extra goals. The team tested two. “Careful PI” told the honeypot to try prompt injection on the attacker if it seemed to be an AI agent. “Convince” told it to persuade the attacker that the application could not be hacked. Both came with trade-offs.
| Honeypot prompt | Requests per interaction | Cost advantage | Detection rate | Functional test pass rate |
|---|---|---|---|---|
| None (simulate faithfully) | 82.6 | 3.6x | 0.24 | 0.84 |
| Careful PI (try prompt injection) | 50.1 | 4.7x | 0.49 | 0.62 |
| Convince (claim it cannot be hacked) | 102.6 | 3.5x | 0.45 | 0.84 |
The Convince prompt produced the longest interactions but nearly doubled the chance of being caught. The prompt-injection version did worst: its injection attempts usually failed, it often gave itself away, and it even tried injections on the harmless functional tests. For anyone building AI scambaiting systems, the lesson is that a decoy should play its part quietly rather than try to be clever.
Weak spots: latency and tokens
The paper names speed as the main weakness of this kind of AI scambaiting. Even the fastest models took more than three seconds per reply, with median latency of 3.3 seconds for Gemini 3 Flash and 13.7 seconds for Claude Haiku 4.5. The agents’ logs showed them repeatedly citing slow responses and timeouts as evidence that they were talking to a honeypot. The authors expect faster, specialised models and better inference hardware to close this gap.
Why AI Scambaiting Is Part of a Wider Psyops Turn
The WIRED newsletter places AI scambaiting inside a broader trend: defenders deliberately targeting the psychology of cybercriminals, not just their servers. WIRED’s own 2024 reporting, which the newsletter links to, described the start of it.
Police trolling ransomware gangs
In February 2024 the UK’s National Crime Agency led Operation Cronos against the LockBit ransomware group, which authorities say extorted more than $500 million. Investigators took over LockBit’s leak site and used it to publish the group’s inner workings, then the usernames of 194 affiliates. A countdown clock preceded the naming of Russian national Dmitry Khoroshev as LockBit’s alleged leader in May 2024. By late May 2024, the NCA said, only 69 of the 194 affiliates had returned to the platform. In April 2024 London’s Metropolitan Police sent personalised videos to about 800 users of the LabHost phishing service: “We’ve been watching you every time you visited us.”
“All of these little things, which in themselves may not be a killer blow, they all add friction,” Don Smith of Secureworks told WIRED at the time. AI scambaiting adds friction in the same way, at a far larger scale.
The ReSCIND programme: psychology as a defence
The US intelligence community’s research agency, the Intelligence Advanced Research Projects Activity, runs a programme called ReSCIND, short for Reimagining Security with Cyberpsychology-Informed Network Defenses. It aims to make attackers less effective by exploiting “innate decision-making patterns and human limitations”, increasing the time, effort and resources they spend. The programme was announced in 2023 and is planned to run for 45 months in three phases, and its main performers are Charles River Analytics, GrammaTech, Peraton Labs, Raytheon Technologies Research Center and SRI International. Programme manager Kimberly Ferguson-Walter told WIRED in 2024: “If you can deter somebody from attacking your network, that’s about as good as it gets.”
AI hacking agents are already in the wild
This branch of AI scambaiting matters because AI attackers are no longer theoretical. In a paper first posted in October 2024, researchers Reworr and Dmitrii Volkov described an SSH honeypot adapted to spot LLM-driven attackers using prompt injection and response timing. Over about three months of public deployment it logged 8,130,731 hacking attempts and identified eight potential AI agents. That is a tiny share, but it showed the early stages of a trend that HoneyVal’s authors now build their whole evaluation around.
The Scale of the Problem AI Scambaiting Faces
The numbers behind online fraud explain why defenders are turning to AI scambaiting and other new tactics. They also put the bot fleets in perspective.
What the loss figures say
The FBI’s Internet Crime Complaint Center received 1,008,597 complaints in 2025, with reported losses of $20.877 billion, up from $16.6 billion in 2024. Investment fraud was the largest category at about $8.65 billion, followed by business email compromise at $3.05 billion and tech support scams at $2.13 billion. Cryptocurrency investment fraud alone accounted for $7.2 billion.
In the UK, UK Finance’s Annual Fraud Report 2026 said criminals stole £1.28 billion through payment fraud in 2025, an increase of 4%. Mobileum’s announcement cited the Global Anti-Scam Alliance’s estimate that scammers stole $442 billion worldwide in 2025. Set against figures like these, even 600,000 diverted calls is a small dent, which is why AI scambaiting companies stress intelligence over volume.
Scammers are using AI too
The 2025 IC3 report was the first to count complaints with an AI element: 22,364 of them, with adjusted losses above $893 million. Most of that, about $632 million, came from investment scams in which AI helped generate thousands of convincing conversations or fake celebrity videos. Business email compromise involving AI accounted for over $30 million, AI-linked tech support scams for about $19.5 million and romance scams with a likely AI link for about $19 million. Apate’s research suggests 20% to 30% of scam text conversations already involve AI. We have covered the same shift in AI-powered dating app scams and the cloned-voice messaging scam at Intesa.
Industrial-scale scam compounds
Much of this fraud comes from organised operations. The IC3 report says cryptocurrency investment scams are “largely perpetrated by organized criminal enterprises based in Southeast Asia using victims of human trafficking as forced labor”, and WIRED has used satellite images to show scam compounds continuing to expand. That matters for AI scambaiting in two ways: the targets are businesses with scripts, managers and quotas, so wasted hours have a real cost, and some of the people on the other end of the line may be trafficking victims themselves.
The Limits and Risks of AI Scambaiting
The early evidence for AI scambaiting is encouraging, but there are important caveats.
An arms race between bots
If 20% to 30% of scam texts already involve AI, defensive bots will increasingly be talking to attacking bots. Kaafar argues that game theory favours the defender, because the defensive bot only needs to extract information while the scam bot has to get its target to act, such as sending money. That is a reasonable argument, but it is a company claim, not a published result. Scammers can also respond by filtering out numbers that waste their time, testing for bot behaviour or switching channels.
Most AI scambaiting evidence is self-reported
Apate’s call volumes, hours wasted and savings estimates have not been independently checked, and O2 published no figures on losses prevented. The HoneyVal results are stronger, with open code and repeated runs, but they come from a lab setting with 16 test applications, not live attacks. Neither kind of AI scambaiting has yet shown a measurable fall in overall fraud losses.
Honeypots can be found and can backfire
HoneyVal showed that a defender’s extra cleverness can make a decoy easier to detect. Slow responses give LLM honeypots away, and an attacker that learns to spot them can avoid them or feed them false information. A honeypot that is recognised also tells the attacker something about the defender’s network and habits.
Ethical and legal questions
Recording and analysing conversations with scammers raises data protection questions, especially when intelligence is shared between banks, telcos and police across borders. Organisations considering AI scambaiting should take legal advice on call recording, data retention and lawful sharing in each country where they operate. The trafficking issue raises a harder question: wasting a scam compound worker’s time may hurt the operation, but it may also put pressure on a person who is not there by choice.
What AI Scambaiting Means for UK Businesses
Most UK organisations will not run a bot army, but the ideas behind AI scambaiting already apply to everyday security.
Where AI scambaiting and deception fit in a security stack
Deception tools, from honeypots to fake credentials planted on a network, give early warning when someone is moving around where they should not be. LLM-backed decoys make those tools more convincing and cheaper to run. They work best alongside the basics: patching, multi-factor authentication, monitoring and regular penetration testing to find weaknesses before attackers do. Our IT security team can help assess where deception would add value.
Questions to ask an AI scambaiting or deception vendor
| Question | Why it matters |
|---|---|
| How do you measure losses prevented, not just minutes wasted? | Engagement metrics do not prove that real customers were protected |
| Has anyone outside the company verified your figures? | Most published numbers in this field are self-reported |
| What happens to the intelligence you collect, and where is it stored? | UK GDPR and data-sharing rules apply to recordings and identifiers |
| How often do attackers detect your decoys? | A detected honeypot gives attackers information about you |
| How does the system respond to AI-driven attackers? | Bot-to-bot conversations behave differently from human scams |
| How fast does it respond? | Slow replies are the main way agents spot LLM honeypots |
Practical steps you can take now
Staff training still matters most, because the scams AI scambaiting fights are aimed at people. Teach staff to verify any change to payment details through a known phone number, to treat urgent requests from “the bank” or “IT support” with suspicion, and to forward scam texts and report scam call numbers to 7726, the free UK reporting service run by mobile networks. Tools that check suspicious messages, such as the one we covered in Amazon’s scam message verification for Alexa, can help too, but they do not replace a clear process for approving payments.
AI Scambaiting FAQ
What is AI scambaiting?
AI scambaiting uses AI bots that pose as potential victims to waste scammers’ time, keep them away from real people and collect intelligence such as mule accounts, phone numbers and scam websites. The same idea applied to hacking uses LLM-powered honeypots to engage AI attackers.
How does Apate’s AI scambaiting work?
Banks and telcos route suspected scam calls and messages to Apate’s bots, which have varied personas, accents and habits. The bots stay sceptical but engaged, sometimes for over two hours, and pass the intelligence they gather back to their clients.
Does AI scambaiting reduce fraud losses?
There is no independent evidence yet. Apate estimates about 13 million dollars saved for one telco over six weeks, but that is its own figure. Fraud losses reported to the FBI rose to $20.877 billion in 2025.
Do LLM honeypots fool AI hacking agents?
In the HoneyVal study, LLM honeypots were detected 24% of the time on average with the default prompt and held attackers for 82.6 requests on average, against 30.6 for rule-based decoys. Slow responses were the most common giveaway.
Can a business use AI scambaiting tools?
Mainly through suppliers. Telcos and banks buy platforms such as Apate’s, while organisations can use deception tools and honeypots on their own networks. Take advice on data protection and call recording before deploying anything that records conversations.
How do I report a scam call or text in the UK?
Forward scam texts to 7726, and to report a scam call, text 7726 with the word “call” followed by the caller’s number. Report fraud losses to your bank straight away.
References
AI Is Getting Really Good at Messing With Cybercriminals (WIRED)
Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots (arXiv)
Honeyval code repository (Google Research, GitHub)
Fake AI victims are scam baiting 600,000 fraudsters every month (Cointelegraph Magazine)
Australia-based Apate.ai takes anti-scam AI tech abroad with Mobileum deal (ARN)
Fighting Fire with Fire: Mobileum and Apate Shut Down Scam Operations From the Inside Out (Mobileum)
O2 unveils Daisy, the AI granny wasting scammers’ time (Virgin Media O2)
O2’s AI granny Daisy unveils what she has learnt from scammers (Virgin Media O2)
Cops Are Just Trolling Cybercriminals Now (WIRED)
LLM Agent Honeypot: Monitoring AI Hacking Agents in the Wild (arXiv)
SoK: Honeypots and LLMs, More Than the Sum of Their Parts? (arXiv)
2025 Internet Crime Report (FBI IC3)
Annual Fraud Report 2026 (UK Finance)
Satellite images reveal how giant scam compounds keep on expanding (WIRED)
More AI coverage: explore Progressive Robot's AI Models, Tools & Releases hub — hands-on reviews, setup guides and benchmarks in one place.